ZeroHour

CVE-2026-87634

mass

Use-after-free in Chrome WebPackaging allows potential sandbox-escaping code execution

CVSS 3.1
9.6 critical
EPSS
<1%p33
Published
()
Modified
AI analysis

CVE-2026-87634 is a use-after-free vulnerability in the WebPackaging component of Google Chrome, triggerable by a remote attacker who persuades a user to open a crafted HTML page. If successfully exploited, the attacker could potentially execute arbitrary code outside of the browser's sandbox, although Google's Chromium team rates the issue as Low severity despite the critical-sounding 9.6 CVSS score. The flaw affects Google Chrome versions prior to 153.0.8010.36, and given Chrome's enormous install base, this potentially touches billions of users until auto-updates complete. There is currently no evidence of exploitation: the bug is not in CISA's Known Exploited Vulnerabilities catalog, EPSS assigns only a 0.3% probability of exploitation within 30 days, and no public proof-of-concept is known. Patched builds are already shipping through Chrome's auto-update mechanism, so the vulnerable population should shrink quickly.

What to do: Update Google Chrome to 153.0.8010.36 or later; the fastest path is to force a check via Settings > About Chrome, which applies the update and relaunches the browser. Administrators should verify installed browser versions through endpoint management or EDR telemetry and confirm auto-update is enabled across the fleet. Given the Low severity rating, absence of a public PoC, and no known exploitation, standard patch-cadence handling is reasonable rather than emergency remediation.

Affected
Google Chromeprior to 153.0.8010.36
Estimated exposure
massbillions of Chrome users are potentially affected until auto-update to 153.0.8010.36 completes — Chrome is the world's dominant desktop browser (roughly 65% browser market share per public usage statistics, with billions of active users), and every installation below 153.0.8010.36 is affected until Chrome's automatic updates deliver…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)

Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.